Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_tools
windows_first
missing_linux_example
Summary
The documentation demonstrates a moderate Windows bias. Windows-specific event sources (e.g., Windows Security Events, Windows Forwarded Events) are listed explicitly, and device-related enrichments and examples predominantly reference Windows (e.g., DeviceFamily: Windows, OperatingSystem: Windows 10). There is little mention of Linux or macOS equivalents, and no examples or guidance are provided for non-Windows endpoints or logs. The documentation assumes a Windows-centric environment for device and security event analysis, which may create friction for organizations with significant Linux/macOS infrastructure.
Recommendations
  • Explicitly mention support for Linux/macOS endpoints and their log sources, if available.
  • Add examples and enrichment fields relevant to Linux/macOS devices (e.g., DeviceFamily: Linux, OperatingSystem: Ubuntu, macOS).
  • Clarify whether UEBA supports Linux/macOS security events and how to onboard these sources.
  • Provide parity in documentation tables and sample values for non-Windows operating systems.
  • If Linux/macOS support is limited, clearly state the limitations and provide guidance for mixed environments.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-13 06:17 #107 completed Biased Biased
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-10 00:00 #92 completed Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean